CVE-2024-39335: Mahara

Critical severity, CVSS 9.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed to an institution administrator under certain conditions via the 'Current submissions' page: Administration -> Groups -> Submissions.

Affected products

  • Mahara Mahara: from 23.04.0, before 23.04.6 (fixed in 23.04.6); from 24.04.0, before 24.04.1 (fixed in 24.04.1)

Published 2025-08-26. Last modified 2026-06-17.